Vulnerabilities / Threats
10/3/2013
05:22 PM
Martin Lee
Martin Lee
Commentary
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Next-Gen Spam: Quality Over Quantity

The industry has been remarkably innovative in developing business models to extract money from the unwary.

The sustained drop in spam volumes since 2010 has coincided with a change in tactics. Anti-spam nonprofit Spamhaus says just 100 operations generate 80% of spam, and these specialists are moving away from indiscriminate, high-volume mailings and instead fine-tuning their campaigns. Spammers know, for instance, that users are less likely to open messages during the weekend, so they've reduced the volume of messages sent on Saturday and Sunday by 25% compared with the rest of the week. It's marketing 101 -- make messages timely and relevant to the audience, send them at the most opportune moment, improve click-through rates.

Meanwhile, spammers are counteracting anti-spam measures. Botnets can check if an individual member's IP address is blacklisted as a sender of spam and if so, assign a different task to that machine. They can spread a spam campaign across a wide range of IP addresses, so each address sends only a small number of emails, thus minimizing the chance of the spam being identified by the telltale sending of large volumes of messages from a single source.

And where once spammers had to hang around underground forums to gain access to those botnets, a shadow economy devoted to servicing the industry has sprung up. The advent of professional spammer services means that access to high-volume "bulletproof" email servers is only a search engine query away. The unique selling point of these companies is that they send email without the inconvenience of having services withdrawn over complaints about spam, and hence, serve customers for whom a takedown-resistant service is important. Such services are widely advertised, with transparent pricing plans and service levels. Spammers can even pay by credit card. These services operate without fear of legal reprisals -- and with a willingness to go on the attack.

Spammers Bite Back

In March, Spamhaus added the bulletproof hosting provider CyberBunker to its directory of suspect IP addresses; this list is widely used to block connections suspected of sending spam. Shortly after, a major distributed denial-of-service attack was launched against Spamhaus's systems. Using a list of poorly configured DNS servers, the attackers sent small DNS requests, spoofed to appear to originate from Spamhaus's IP addresses, seeking large amounts of DNS data. Think of an attacker using a small Post-it note to deliver a copy of the Yellow Pages to a victim's address. Ultimately, the attack failed, Spamhaus was able to continue its work, and two alleged perpetrators have been arrested and charged in relation to the crime. But such battles are expensive, and arrests are few and far between.

Meanwhile, spammers have become adept at hijacking breaking news as an effective method of engaging with users. In the aftermath of the Boston Marathon bombing on April 15, spammers launched two large-scale campaigns with fake news bulletins designed to prey on interest around the attack. Both sets of emails contained links to malicious websites that attempted to install malware.

cnn breaking news email

At its peak on April 17, Boston Marathon bombing-related spam comprised 40% of all spam messages delivered worldwide. This is unusual. Typically, spammers prefer to send spam in lower volumes to avoid triggering security alerts, but spammers are keen to make the most of a topic with broad interest but possibly a short lifespan.

When current news events aren't compelling enough, spammers are not beneath inventing their own news to entice users to open their messages. During the period of discussion regarding the possibility of international military action against Syria, spammers sent fake news updates announcing that bombings had already taken place. Again, these emails linked to malicious websites serving malware rather than the "full story."

obama speech email

Protecting Users

Teaching users not to click links in suspicious emails is a cornerstone of security training. However, even the most highly trained user will be tempted to open a message when faced with a convincing news report that is compelling and consistent with current events. Recipients are less likely to see emails that are relevant to their interests as suspicious, so make sure you regularly apprise employees of current spam tactics.

Still, as the spam industry professionalizes, expect deep analysis by spammers of the types of messages that users are likely to open and with which they're likely to interact. The less spam looks like spam, the more important it is to keep malicious messages from ever hitting user inboxes. When evaluating anti-spam options, look for an advanced threat intelligence network that can consider the context of a message, the reputation of the sender, the reputation of the sending IP address, and the nature of websites hosting any links within the email.

Plan for a few malicious messages being missed by anti-spam systems or accessed through other means, such as via personal webmail accounts. In these cases, the next defense is a Web scanning tool that blocks access to links that are actively being distributed in spam campaigns; even if a user has accessed a message, the device can prevent the link from being opened.

Blocking websites based on reputation is particularly useful to foil gangs that use shady hosting companies to spread malicious content, not only by email but also via social networking or other techniques. Obfuscated malware can be particularly difficult to detect using traditional signature-based antivirus techniques.

And remember that all this expensive technology is useless if the email is delivered to a junk mailbox, where someone can click on messages that look like legitimate email. If you don't have enough confidence in the false-positive rate of your anti-spam system to prevent users from having access to blocked spam email, reconsider your strategy.

One thing is for certain: Spammers aren't getting any dumber. The spam community, and the ecosystem that supports it, will continue to evolve in terms of range and professionalism. Spammers already convincingly spoof legitimate news sources; the next step must be to convincingly spoof messages from a user's employer, friends and family. Only by keeping these messages away from intended recipients can we hope to stop feeding the beast.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
OtherJimDonahue
50%
50%
OtherJimDonahue,
User Rank: Apprentice
10/4/2013 | 6:17:35 PM
re: Next-Gen Spam: Quality Over Quantity
I gave up checking my work spam years ago--just get too much.

I used to check my personal spam periodically because I only got a few per day and sometimes nonspam would get caught. But after my spam level went up to about 250 a day, that was no longer practical.
Lorna Garey
50%
50%
Lorna Garey,
User Rank: Ninja
10/4/2013 | 5:56:08 PM
re: Next-Gen Spam: Quality Over Quantity
I stopped looking at my spam email. I figure, if it's important, they'll try again or ring me. I'd rather miss a message than end up calling IT In shame because my PC has ransomware (not that this has ever happened mind you ...)
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-4514
Published: 2014-10-21
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to the getDebugInfo function.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.